How Blake from Downtown would approach IT security
endif; ?>In David Mamet’s 1992 film “Glengarry Glen Ross,” Alec Baldwin’s character Blake – sent by the firm’s owners Mitch and Murray to lay down some tough love on the salesmen at a remote office of their real estate agency – uses as one of his motivational tools the acronym “AIDA.” It stands for “Attention, Interest, Decision, Action” and it has a lot to teach us about how information security is addressed today. If Blake were actually a cybersecurity ringer speaking to an audience of CEOs about the state of their information security programs, I think he would interpret those four words for his audience in a manner similar to this:
“So, you’ve just been hacked. Do I have your attention now? Good. Are you interested in fixing this problem so it doesn’t happen again? I know you are, because it’s secure your data, or get owned. ‘D’ for decision… have you made your decision to build a security program that actually reduces risk and the likelihood of future successful attacks? Good. Now, are you ready to act on that and make it happen?”
While Blake’s psychopathic speech may not exactly be the kind of model language found in “How to Win Friends and Influence People,” it certainly has a familiar ring to security practitioners. So often, what we do is reactionary: we experience a data breach, or a disgruntled employee, or a natural disaster that leaves our systems and information compromised … and only then do we attempt to retroactively fix the root cause of the problem.
However, that’s often not for a lack of trying; for all of the budgetary restrictions, seeming lack of interest by executive management, employees who are uneducated about security, and other issues, often the real reason CISOs, security analysts and other practitioners in our industry fall short is due not to a failure to put security controls in place, but a failure in how to measure their effectiveness. For security programs, metrics are everything. We know there is no such thing as 100% secure, so we need to make every dollar, every technology and every person count. Simply saying, “we installed a firewall, an IPS, antivirus, and email filter, so we’re good…” is no longer a sufficient way to measure our success in information security.
So what are the information security metrics we should be looking at? While that will ultimately depend on the specifics of the organization, here are some high-level, quantifiable metrics that we should be evaluating within the networks, systems and data that we manage:
- Risk Tolerance. A risk-based approach to security is by far the most effective way of figuring out what your organization owns, what all of it is worth, and what threats exist to steal or destroy it. But one key question that’s often overlooked in risk assessments is “what level of risk are we willing to accept?” Since there’s no such thing as 100% secure, there will always be residual risk. Quantifying that residual risk, explaining what it means to stakeholders, and re-evaluating it periodically is critical to understanding the overall level of risk posture in the enterprise. It also doesn’t hurt to get written signoff from senior management to ensure that they accept that the risk is critical to understanding; in the event that something goes wrong, fixing it needs to be a collaborative effort, not a blame-game.
- Threats Detected Over Time. If you’re like most organizations, you’ve got lots of security tools telling you about threats that they’ve identified: malware, externally-launched attacks, spam and a host of other threats can be detected using signature-based technologies. Bringing the data from all of those tools together into a single console and mapping them out (for example, by using a SIEM) is a great way of getting the big picture of threats. A massive increase in external attacks or spam, for example, might indicate that your organization is being singled-out. Of course, not every threat comes with a nice, neat signature – APTs, insider threats, and others may not have an easy red flag. For that reason, it’s critical to be able to measure not just signature-based threats that have been detected, but also general abnormalities that are occurring across the environment: the user who’s opening or copying a much larger number of files than normal; the abnormal network protocols and destination IP’s that a workstation is communicating with on the network; the database server that’s suddenly going from 10% CPU utilization to 80%. All of these things can be indicators of a potential threat, regardless of whether they trigger a signature-based alert or not.
- Prescriptive Configuration Baselines. Unpatched and misconfigured systems are the low-hanging fruit of attacks. The more assets you have – servers, workstations, laptops, firewalls, routers, etc. – the bigger the potential likelihood that you have a hole somewhere that will let a smart attacker or piece of malware through your network. Measuring your assets against prescriptive configuration baselines are an effective way of ensuring that risks from this common attack vector are minimized. Fortunately, these baselines come from a broad range of sources: vendor security recommendations, publicly-available guidance like CIS benchmarks and DISA STIGs, or even internal “gold disk” configurations within your organization.
This certainly isn’t an exhaustive list, but it’s a good start that contains some key metrics that should apply to every risk-based information security program. Now go out there, determine which additional metrics are going to give you the objective information you need to ensure your security program is working to minimize risk, and remember: as Blake from downtown would say, “Have I got your attention now? Good.”




